
Send Emails with Mandrill Security & Risk Analysis
wordpress.org/plugins/send-emails-with-mandrill'Send Emails with Mandrill' sends emails that are generated by WordPress through Mandrill, a transactional email service powered by MailChimp.
Is Send Emails with Mandrill Safe to Use in 2026?
Generally Safe
Score 99/100Send Emails with Mandrill has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "send-emails-with-mandrill" plugin version 1.6.2 reveals a generally good security posture, with no identified attack surface points, dangerous functions, or unsanitized taint flows. The code demonstrates strong practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The presence of capability checks further enhances security by ensuring appropriate user permissions are verified.
However, a previous vulnerability history of one known CVE, though currently patched, warrants attention. While the recent vulnerability was listed as medium severity and is now patched, it highlights a past weakness that could indicate a tendency for certain types of security flaws, specifically missing authorization. The absence of nonce checks is also a minor concern, especially if any future AJAX or REST API endpoints are introduced without proper authorization.
Overall, the plugin appears to be well-developed from a security perspective, with its strengths lying in its minimal attack surface and secure coding practices for SQL and output handling. The past vulnerability, however, suggests a need for continued vigilance and thorough auditing of any new features to prevent similar issues from arising.
Key Concerns
- Previous medium severity CVE
- No nonce checks implemented
Send Emails with Mandrill Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Send Emails with Mandrill <= 1.4.1 - Missing Authorization
Send Emails with Mandrill Code Analysis
Output Escaping
Send Emails with Mandrill Attack Surface
Maintenance & Trust
Send Emails with Mandrill Maintenance & Trust
Maintenance Signals
Community Trust
Send Emails with Mandrill Alternatives
ActiveCampaign Postmark for WordPress
postmark-approved-wordpress-plugin
The officially-supported ActiveCampaign Postmark plugin for Wordpress.
SMTP2GO for WordPress – Email Made Easy
smtp2go
Resolve email delivery issues, increase inbox placement, track sent email, get 24/7 support, and real-time reporting.
WPO365 | MICROSOFT 365 GRAPH MAILER
wpo365-msgraphmailer
Send WordPress emails from a M365 / Exchange Online Mailbox using Microsoft Graph, leveraging OAuth for authentication which is more secure than SMTP
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
Swift SMTP (formerly Welcome Email Editor)
welcome-email-editor
Swift SMTP is a free & simple SMTP Plugin for WordPress.
Send Emails with Mandrill Developer Profile
7 plugins · 11K total installs
How We Detect Send Emails with Mandrill
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/send-emails-with-mandrill/assets/css/wpmandrill-admin-style.css/wp-content/plugins/send-emails-with-mandrill/assets/js/wpmandrill-admin-script.js/wp-content/plugins/send-emails-with-mandrill/assets/js/wpmandrill-admin-script.jssend-emails-with-mandrill/assets/css/wpmandrill-admin-style.css?ver=send-emails-with-mandrill/assets/js/wpmandrill-admin-script.js?ver=HTML / DOM Fingerprints
SEWM_VERSIONSEWM_BASESEWM_URLSEWM_PATH